Release date:
2026-09-25 15:38:23 UTC
Description:
- CVE-2026-56850: https: distinguish PFX object-array agent keys, so an
https.Agent pool name built from a `pfx` array of { buf, passphrase } objects
folds in each entry's certificate and passphrase instead of stringifying the
array to the literal `[object Object]`, which made every such array share one
pool entry and let a request reuse a keep-alive socket or a resumed TLS
session authenticated with a different client certificate
- CVE-2026-58042: dns: handle large resolveAny address replies, by sizing the
A and AAAA TTL buffers from the reply's ANCOUNT instead of a fixed 256
entries, so a dns.resolveAny() answer carrying more than 256 A records no
longer trips CHECK_EQ(naddrttls, a_count) and aborts the process
- CVE-2026-58045: zlib: throw on out-of-bounds write buffers, so a TypedArray
whose byteLength is spoofed with a getter makes the synchronous node:zlib
entry points raise a catchable RangeError (ERR_OUT_OF_RANGE) instead of
failing a CHECK in CompressionStream::Write() and aborting the process
Updated packages:
-
alt-nodejs12-nodejs-12.22.12-33.el7.x86_64.rpm
sha:4e109e5b7755497a2b49eb5a73fceb19900e4ffefbe25317b07a154639974eec
-
alt-nodejs12-nodejs-devel-12.22.12-33.el7.x86_64.rpm
sha:56215392a0bc13db4d1e323965812f04bb82353639826f23ae6f162a4e2da83a
-
alt-nodejs12-nodejs-docs-12.22.12-33.el7.noarch.rpm
sha:d07b4eb9aecfc7619e38f2e3dd08e944d6081653e19d3b2a01a7aca94a39c81b
-
alt-nodejs12-npm-6.14.16-12.22.12.33.el7.x86_64.rpm
sha:0b73188f4505f0322abea7dd76ae6f5b7c8572c5927c58e8d9a8f5caefe78cbd
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.